Alert: Heartbleed attack. Image: gotidbits.com |
If you are just starting a business and an online business, or an online store that serves transaction or purchase online using a credit card payment, then you need to be vigilant. You certainly have heard Heartbleed bug attacks, resulting in a loss on the online entrepren
Are you free from attack Heartbleed bug?
Heartbleed is a new security hole that can open millions of passwords. Even more surprising, the threat of Heartbleed bug has lived for more than two years with no one party is aware of its existence.
Researchers at Codenomicon, a security company in Finland, which is one of its members is also a Google researchers have discovered the existence Heartbleed. We have heard that Heartbleed has successfully attacked almost all web-based OpenSSL, and steal user data, including the password, credit card, email, and so on. Certainly the credit card owners worried about losing money and other losses.
What is surprising to many people is even though the website has been marked with a lock https:// in the browser, Heartbleed can still go in and parse the data encryption that is in the site. This is obviously very dangerous to start your new online business or online store.
The website owner must be able to protect the data or credit card information of their customers. Of course your customers, do not want to lose their credit card data. We already know that the credit card data theft syndicate is a serious threat.
We have heard that a big business like Google and Yahoo become the main target Heartbleed, but the owner of the security startup Lasline, Giovanni Vigna has a different view. According to him, it turns out smaller companies it is targeting Hearbleed. Why? Small companies do not yet have a strong shield, to protect them from Heartbleed.
You do not need to panic, because there is always a solution to solve it, so you can rely on some tips as mentioned below:
1. OpenSSL update with a new version that has been equipped with a fix. This will close the security gap and make you re-secure software. In the new version has been given a new certificate (read: secret key) which will tell the user to change their password.
2. Notify all users and your employees that your site has been returned safe and advise them to change their usernames and passwords. It is recommended that the circuit needs to do a password change: change now, once a week and once a month. When did you have to do it? Of course, from this moment. It is very important that you do so that your website free of problems that would be detrimental your company.
3. Cyberattack would surely cripple the central business you run, needs a lot of cost to repair and damage the image of your business being pioneered. Therefore you should immediately diagnose your web security as soon as possible, and were accustomed to meeting your IT staff, so you can anticipate cyber attacks as Heartbleed.
There is the best advice that you can do now is to visit a website that can check whether your website has been free from attacks Heartbleed. Please click here.
Heartbleed also targeting the Android smartphones. Image: cultofandroid.com |
Additional advice: you need to suggest to you that security teams more active to get along with peers, so that they always get the latest information about viruses, malware, phishing, and other enemies of other online business. You also need to conduct a special meeting at certain times so that your website is safe from cyber attacks.
If you are the owner of an Android-based smartphone should also be careful, especially if you have important data on your smartphone. Make sure you also change your password on a regular basis, so that your smartphone is not easily penetrated by Heartbleed bugs and other cyber attacks.
Comments
Post a Comment